Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2616▼ 309 respecto a la semana anterior
Críticas / altas1342▲ 71 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC5 Firmware | 27/3/2026 | 17/6/2026 | A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC5 Firmware | 27/3/2026 | 17/6/2026 | A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsOOB of the component POST Request Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC5 Firmware | 27/3/2026 | 17/6/2026 | A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. Such manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC5 Firmware | 26/3/2026 | 17/6/2026 | A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. This manipulation of the argument PPPOEPassword causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 1.0% | — | Tenda AC5 Firmware | 26/3/2026 | 17/6/2026 | A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be… | |
| Analizada | Alta (7.4) | 0.99% | — | Tenda AC5 Firmware | 30/6/2025 | 17/6/2026 | A vulnerability was found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this issue is some unknown functionality of the file /goform/SetSysTimeCfg. The manipulation of the argument time/timeZone leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed… | |
| Analizada | Alta (7.4) | 0.96% | — | Tenda AC5 Firmware | 30/6/2025 | 17/6/2026 | A vulnerability has been found in Tenda AC5 15.03.06.47 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /goform/openSchedWifi. The manipulation of the argument schedStartTime/schedEndTime leads to stack-based buffer overflow. The attack can be launched remotely. The… | |
| Analizada | Alta (7.4) | 0.99% | — | Tenda AC5 Firmware | 9/6/2025 | 17/6/2026 | A vulnerability was found in Tenda AC5 15.03.06.47. It has been classified as critical. Affected is the function formSetRebootTimer of the file /goform/SetRebootTimer. The manipulation of the argument rebootTime leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Alta (7.4) | 0.96% | — | Tenda AC5 Firmware | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Tenda AC5 1.0/15.03.06.47. This affects the function fromadvsetlanip of the file /goform/AdvSetLanip. The manipulation of the argument lanMask leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (7.4) | 0.96% | — | Tenda AC5 Firmware | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Tenda AC5 15.03.06.47. Affected by this issue is the function formSetPPTPUserList of the file /goform/setPptpUserList. The manipulation of the argument list leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC9 FirmwareTenda AC5 Firmware | 30/8/2023 | 17/6/2026 | Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC9 FirmwareTenda AC7 FirmwareTenda AC5 Firmware | 30/8/2023 | 17/6/2026 | Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC9 FirmwareTenda AC5 Firmware | 30/8/2023 | 17/6/2026 | Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC9 FirmwareTenda AC7 FirmwareTenda AC5 Firmware | 30/8/2023 | 17/6/2026 | Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC7 FirmwareTenda AC5 Firmware | 30/8/2023 | 17/6/2026 | Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat. | |
| Modificada | Crítica (9.8) | 1.1% | — | Tenda AC9 FirmwareTenda AC7 FirmwareTenda AC5 Firmware | 30/8/2023 | 17/6/2026 | Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC9 FirmwareTenda AC5 Firmware | 30/8/2023 | 17/6/2026 | Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetStaticRouteCfg. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda Ac10 FirmwareTenda Ac1206 FirmwareTenda AC8 FirmwareTenda AC6 Firmware+3 | 7/8/2023 | 17/6/2026 | Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the formSetVirtualSer function. | |
| Modificada | Crítica (9.8) | 0.85% | — | Tenda Ac10 FirmwareTenda Ac1206 FirmwareTenda AC6 FirmwareTenda AC7 Firmware+5 | 7/8/2023 | 17/6/2026 | Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function. | |
| Modificada | Crítica (9.8) | 0.85% | — | Tenda Ac1206 FirmwareTenda AC5 FirmwareTenda AC9 FirmwareTenda AC8 Firmware+1 | 7/8/2023 | 17/6/2026 | Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda Ac10 FirmwareTenda Ac1206 FirmwareTenda AC6 FirmwareTenda AC7 Firmware+5 | 7/8/2023 | 17/6/2026 | Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda Ac10 FirmwareTenda Ac1206 FirmwareTenda AC8 FirmwareTenda AC6 Firmware+4 | 7/8/2023 | 17/6/2026 | Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the setaccount function. | |
| Modificada | Crítica (9.8) | 0.84% | — | Tenda AC7 FirmwareTenda F1203 FirmwareTenda Fh1205 FirmwareTenda AC5 Firmware+1 | 7/8/2023 | 17/6/2026 | Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function. | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda F1202 FirmwareTenda Fh1202 FirmwareTenda Ac10 FirmwareTenda Ac1206 Firmware+3 | 14/7/2023 | 17/6/2026 | Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromDhcpListClient. | |
| Modificada | Crítica (9.8) | 0.93% | — | Tenda F1202 FirmwareTenda Fh1202 FirmwareTenda Ac10 FirmwareTenda Ac1206 Firmware+3 | 14/7/2023 | 17/6/2026 | Tenda F1202 V1.0BR_V1.2.0.20(408) and FH1202_V1.2.0.19_EN, AC10 V1.0, AC1206 V1.0, AC7 V1.0, AC5 V1.0, and AC9 V3.0 were discovered to contain a stack overflow in the page parameter in the function fromNatStaticSetting. |